What are Cortex Cloud data sources and connectors?
Learn more about Cortex Cloud data sources and connectors with a unified approach to integrations.
Data sources and connectors are the foundational mechanisms used to ingest security and operational data into Cortex Cloud for analysis, correlation, and response. By consolidating data from cloud environments and third-party security tools, Cortex Cloud helps monitor identity risks and secure configurations across your multi-cloud and SaaS ecosystem.
Customer availability by tenant type
The ingestion methods and configuration options available to you in the user interface depend on your tenant onboarding date:
New tenants (onboarded after July 26, 2026): You will primarily interact with the strategic Connector experience. Standalone Marketplace integrations managed by Palo Alto Networks that have been consolidated into connectors are hidden from the catalog to ensure a unified configuration flow. Partner and community-contributed integrations remain available as standalone packs.
Existing tenants (onboarded before July 26, 2026): You will continue to see both standalone Marketplace integrations and unified Connectors. Refer to the specific documentation for each vendor to determine the supported configuration method for your account.
Clarifying terminology: Data sources and Connectors
In the Cortex Cloud user interface (UI), configuring ingestion involves different areas and terminologies depending on the type of connection and your tenant onboarding date. While Cortex Cloud is introducing connectors as a new, unified approach to ingestion, traditional Data Source methods remain supported.
In the current intermediate state, it is important to understand how these terms relate to each other:
Data sources: Represents the traditional method for any integration that provides data to Cortex Cloud. In this documentation, Data Source is used as the category for these traditional ingestion methods, which include:
Data collectors: Built-in tools primarily focused on raw log ingestion. This includes generic logs ingested via XDR Collectors and core ingestion functionalities found using the Data Source Onboarder.
Broker VM applets: Specialized applications running on the Broker VM that function as collectors, such as the Syslog Collector.
Marketplace (integrations): Content packs that include collection integrations. These are typically referred to as data sources in the UI, as integrations that fetch data are configured through the Data Source Onboarder on the Data Sources & Integrations page.
Connectors: The new, unified mechanism for data ingestion. For supported vendors, a Connector groups multiple security capabilities, such as Identity Posture and Data Security, into a single, uniquely named entry with a guided configuration wizard.
While specific components like Data Collectors, Broker VM applets, and Connectors are named explicitly when discussing their unique configuration workflows, they all fall under the foundational goal of ingesting data into Cortex Cloud.
Why are different data sources and connectors necessary?
Cortex Cloud enables you to collect data across a vast and varied enterprise landscape. This necessitates distinct data source types and connectors designed for different environments and needs:
Connectors: Streamline the onboarding of third-party SaaS services by grouping identity and data security capabilities into a single entry with a guided wizard.
Standard data collectors (API/Built-in): These are built-in functionalities primarily focused on ingesting raw logs and security events for core security analysis, parsing, and normalization.
Broker VM data collector applets: These are modular applications installed on a local Broker VM virtual appliance, designed for on-premise data collection needs like the Syslog Collector or Database Collector.
XDR Collectors (XDRC): These are lightweight agents dedicated to on-premise log collection on Windows and Linux host machines.
Cloud Service Provider (CSP) Onboarding: These are specialized wizards for integrating cloud environments, such as AWS, Azure, GCP, and OCI, enabling streamlined setup for asset discovery, cloud posture/runtime security, and log collection.
Marketplace content packs: These packages offer specialized security functionality by bundling both a collection integration (for data ingestion) and automation components, such as playbooks and correlation rules.
Note
Standalone Marketplace integrations managed by Palo Alto Networks are primarily used by existing customers (onboarded before July 26, 2026). New customers will find these integrations consolidated within the new Connector framework, while partner and community integrations continue to be available as standalone Marketplace content packs.
Palo Alto Networks Integrations: Cortex Cloud provides both standard data sources and new unified connectors for Palo Alto Networks products to ensure deep telemetry ingestion.
Cloud Posture and Runtime Security data sources: These data sources provide agentless visibility and real-time control over cloud risks by using cloud-native APIs to monitor misconfigurations and secure container environments.
Current UI and future direction
Cortex Cloud is transitioning toward a unified ingestion experience. While different ingestion methods currently involve distinct workflows, the following table summarizes where to manage them:
Data Source Type
Primary UI Location(s) for Configuration
Key Components
Connectors
Data Sources & Integrations page (Settings → Data Sources & Integrations → + Add New)
Unified wizard for multi-capability vendor integrations.
Standard data collectors
Data Sources & Integrations page (Settings → Data Sources & Integrations → + Add New)
Built-in functionalities primarily focused on ingesting raw logs and security events, such as Okta and Amazon S3.
Broker VM applets
Broker VMs page (Settings → Configurations → Data Broker → Broker VMs)
Specialized applications running on a Broker VM, such as Syslog Collector.
XDR Collectors
XDR Collectors page (Settings → Configurations → XDR Collectors)
Management of XDR Collectors dedicated for on-premise data collection on Windows and Linux machines.
CSP onboarding and standard collectors
Data Sources & Integrations page (Settings → Data Sources & Integrations → + Add New)
Specialized wizards for integrating cloud environments, such as AWS, Azure, and GCP.
Marketplace content packs
Data Sources & Integrations page (Settings → Data Sources & Integrations via Data Source Onboarder, for packs with data ingestion or after a Marketplace install)
Discovery and installation of integration-specific content packs.
Cloud Posture and Runtime Security data sources
Data Sources & Integrations page (Settings → Data Sources & Integrations → + Add New)
Broker VMs page (Settings → Configurations → Data Broker → Broker VMs)
Direct API ingestion or Broker VM applets for monitoring misconfigurations and securing cloud workloads.
Last updated
Was this helpful?
